Skip to main content
DORA Auditor

Article 21: Centralisation of reporting of major ICT-related incidents

Last updated: 1 authoritative sourceDORA Auditor Editorial Team

Article 21 required the European Supervisory Authorities, through the Joint Committee and in consultation with the ECB and ENISA, to report by 17 January 2025 on the feasibility of a single EU Hub that would centralise major ICT-related incident reporting instead of routing it through each national competent authority.

Chapter III, ICT-related incident management · Pillar: ICT Incident Reporting

Key points

  • Mandated a joint ESA feasibility report on a single EU Hub for incident reporting
  • Report covered costs, benefits, risks, and interoperability with other reporting schemes
  • Due to the European Parliament, Council, and Commission by 17 January 2025

How this fits DORA

Article 21 sits within the ICT Incident Reporting pillar. For the full set of obligations and how they interlock, see the DORA requirements overview.

Read the official text

This is an editorial summary. Read the binding text of Article 21 in the consolidated regulation on EUR-Lex.

Sources

  1. Regulation (EU) 2022/2554 (DORA), EUR-Lex